ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1105×

18 examples

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareCOATHANGER

COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices.

T1027
Obfuscated Files or Information
MalwareCOATHANGER

COATHANGER can store obfuscated configuration information in the last 56 bytes of the file `/date/.bd.key/preload.so`.

T1027.002
Software Packing
MalwareCOATHANGER

The first stage of COATHANGER is delivered as a packed file.

T1055
Process Injection
MalwareCOATHANGER

COATHANGER includes a binary labeled `authd` that can inject a library into a running process and then hook an existing function within that process with a new function from that library.

T1057
Process Discovery
MalwareCOATHANGER

COATHANGER will query running process information to determine subsequent program execution flow.

T1059.004
Unix Shell
MalwareCOATHANGER

COATHANGER provides a BusyBox reverse shell for command and control.

T1070.004
File Deletion
MalwareCOATHANGER

COATHANGER removes files from victim environments following use in multiple instances.

T1071.001
Web Protocols
MalwareCOATHANGER

COATHANGER uses an HTTP GET request to initialize a follow-on TLS tunnel for command and control.

T1083
File and Directory Discovery
MalwareCOATHANGER

COATHANGER will survey the contents of system files during installation.

T1095
Non-Application Layer Protocol
MalwareCOATHANGER

COATHANGER uses ICMP for transmitting configuration information to and from its command and control server.

T1140
Deobfuscate/Decode Files or Information
MalwareCOATHANGER

COATHANGER decodes configuration items from a bundled file for command and control activity.

T1190
Exploit Public-Facing Application
MalwareCOATHANGER

COATHANGER is installed following exploitation of a vulnerable FortiGate device.

T1222.002
Linux and Mac Permissions
MalwareCOATHANGER

COATHANGER will set the GID of `httpsd` to 90 when infected.

T1543.004
Launch Daemon
MalwareCOATHANGER

COATHANGER will create a daemon for timed check-ins with command and control infrastructure.

T1564.001
Hidden Files and Directories
MalwareCOATHANGER

COATHANGER creates and installs itself to a hidden installation directory.

T1573.002
Asymmetric Cryptography
MalwareCOATHANGER

COATHANGER connects to command and control infrastructure using SSL.

T1574
Hijack Execution Flow
MalwareCOATHANGER

COATHANGER will remove and write malicious shared objects associated with legitimate system functions such as `read(2)`.

T1574.006
Dynamic Linker Hijacking
MalwareCOATHANGER

COATHANGER copies the malicious file /data2/.bd.key/preload.so to /lib/preload.so, then launches a child process that executes the malicious file /data2/.bd.key/authd as /bin/authd with the arguments /lib/preload.so reboot newreboot 1. This injects the malicious preload.so file into the process with PID 1, and replaces its reboot function with the malicious newreboot function for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.